CVE-2026-102267
- EPSS 0.16%
- Veröffentlicht 28.09.2026 21:17:14
- Zuletzt bearbeitet 07.10.2026 20:27:45
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS endpoint return...
CVE-2026-102266
- EPSS 0.18%
- Veröffentlicht 28.09.2026 21:17:14
- Zuletzt bearbeitet 07.10.2026 20:55:07
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a trusted JWK Se...
CVE-2026-101918
- EPSS 0.29%
- Veröffentlicht 28.09.2026 21:17:13
- Zuletzt bearbeitet 07.10.2026 20:59:17
PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled ...
CVE-2026-101917
- EPSS 0.35%
- Veröffentlicht 28.09.2026 21:17:13
- Zuletzt bearbeitet 07.10.2026 21:01:01
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a negative cache or minimum refresh interval. This occurs when unauthenticate...
CVE-2026-48525
- EPSS 0.37%
- Veröffentlicht 28.05.2026 15:11:12
- Zuletzt bearbeitet 01.06.2026 17:45:15
PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment b...
CVE-2026-48523
- EPSS 0.13%
- Veröffentlicht 28.05.2026 15:10:19
- Zuletzt bearbeitet 16.09.2026 20:16:33
PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-...
CVE-2026-48526
- EPSS 0.4%
- Veröffentlicht 28.05.2026 15:09:09
- Zuletzt bearbeitet 10.09.2026 13:20:19
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing a...
CVE-2026-48524
- EPSS 0.34%
- Veröffentlicht 28.05.2026 15:07:35
- Zuletzt bearbeitet 01.06.2026 17:44:55
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified to...
CVE-2026-48522
- EPSS 0.22%
- Veröffentlicht 28.05.2026 15:00:30
- Zuletzt bearbeitet 02.06.2026 17:16:35
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHan...
CVE-2026-32597
- EPSS 0.27%
- Veröffentlicht 12.03.2026 21:41:50
- Zuletzt bearbeitet 10.09.2026 13:18:12
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, t...